budge
Warn
Audited by Socket on May 14, 2026
1 alert found:
AnomalyAnomalyreferences/INSTALL.md
LOWAnomalyLOW
references/INSTALL.md
This fragment integrates a third-party CDN-hosted self-executing script (https://www.budge.design/budge.iife.js) into multiple frameworks with no SRI/integrity pinning shown, creating a supply-chain execution risk. It also describes MutationObserver-based activation using DOM/class/style changes and optional JSON config via a hidden data-budge element, increasing runtime behavioral opacity. No direct evidence of credential theft/exfiltration is present in the shown code, but the actual IIFE content is not provided, so malicious behavior cannot be fully assessed.
Confidence: 63%Severity: 55%
Audit Metadata